Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the creation of a local administrative account with a hidden naming convention (ending in $) accompanied by a cluster of registry modifications designed to obscure the account from the logon screen, enable WDigest plaintext credential caching, relax RDP authentication requirements (disable NLA, enable RDP), and disable UAC remote restrictions. This activity is highly indicative of post-exploitation persistence and credential harvesting configurations following initial access via SQL server exploitation.
Detects a UAC bypass sequence associated with the ChainScript/Rapuncel loader, where a process invokes an 'elevation:Administrator!new' COM moniker (such as CMSTPLUA or ICMLuaUtil) followed by the execution or hollowed-out spawning of 'ServiceModelReg.exe' to achieve elevated privileges.
Detects execution of an XMRig cryptominer masquerading as the legitimate system process 'smss.exe' from a non-standard file path. This detection specifically identifies the presence of the WinRing0x64.sys kernel driver, often used by XMRig for hardware MSR access, and detects preceding malicious activity involving UnRAR extraction of the miner using a specific password.
Detects the installation or configuration of the NvFsFilter (Alinubx.sys) persistence driver, often associated with malicious behavior that continuously terminates security software processes to allow for persistent unauthorized activity after system reboots.
Detects anomalous file staging activity combined with keyword-matched file access or suspicious Steam application launches, characteristic of the Rapuncel (BoryptGrab) malware's credential and crypto-wallet harvesting routine.
This rule detects the loading of the known vulnerable NvFsFilter (Alinubx) driver, followed by the abrupt cessation of multiple active AV/EDR processes within a 30-minute window. This behavior is indicative of a Bring Your Own Vulnerable Driver (BYOVD) attack, where the driver is used to execute kernel-mode commands to terminate security software, bypassing standard protection mechanisms.
Detects network activity associated with the RatHat Android malware, specifically focusing on its use of WebSocket-based FRP (Fast Reverse Proxy) tunnels for command and control, session initialization, configuration retrieval, and local loopback proxy communication.
Detects network activity associated with the RatHat Android malware, specifically the exfiltration of accessibility tree data and calls to Google's Generative Language API (gemini-2.5-flash-lite) for UI target resolution and automation.
Detects the presence of known RatHat Go-based command agents (liblocal-service.so) or frpc reverse-proxy clients (libmedia_codec.so) when staged within temporary directories such as /data/local/tmp on Android devices, often following manual ADB shell interaction.
Detects network activity associated with the NeedyMantis malware, including TLS SNI traffic to its hard-coded C2 domain, initial beaconing over HTTPS to specific paths, and potential exfiltration or reconnaissance markers in the server's Set-Cookie header response.
Detects instances where the Node.js runtime process (node.exe) spawns a command shell (cmd.exe) or PowerShell (powershell.exe). This pattern is frequently used by malicious Node.js-based applications, RATs, or web shells to execute arbitrary commands on a compromised host.
Detects network activity associated with the NeedyMantis malware, including TLS SNI traffic to its hard-coded C2 domain, initial beaconing over HTTPS to specific paths, and potential exfiltration or reconnaissance markers in the server's Set-Cookie header response.
Detects network activity associated with the RatHat Android malware agent, including C2 tasking, Go agent 'frpc' tunnel configuration retrieval, tunnel deployment status reporting, and internal loopback C2 server communication.
Detects network activity associated with the RatHat Android malware, specifically identifying C2 data exfiltration API calls over FRP (FRP/Go Agent) tunnels and WebSocket handshake traffic for command-and-control communication.
Detects instances where the Node.js runtime process (node.exe) spawns a command shell (cmd.exe) or PowerShell (powershell.exe). This pattern is frequently used by malicious Node.js-based applications, RATs, or web shells to execute arbitrary commands on a compromised host.
Detects the RatHat post-uninstall persistence sequence on Android devices. This rule identifies a daemon that silently reinstalls an APK using 'pm install' from a temporary directory, followed by the programmatic enabling of Accessibility Service settings without user interaction.
Detects outbound network traffic associated with the NeedyMantis actor, specifically identifying a hardcoded outdated Firefox/21.0 User-Agent in HTTP requests attempting to upgrade to a WebSocket connection, as well as direct TLS communication with the identified C2 domain corp.tripswithengine.com.
Detects the execution of the 'getevent' debugging utility within an Android ADB shell context, specifically targeting raw input events from /dev/input. This behavior is indicative of potential unauthorized input monitoring, such as capturing PINs, patterns, or passwords via touch coordinate tracking.
Detects communication patterns associated with the RatHat Android banking trojan. The rule identifies a multi-stage C2 flow: first, the device fetches malicious overlay configurations (templates for spoofed login screens) and subsequently exfiltrates captured credentials or form data to the adversary's infrastructure via POST requests.
Detects RatHat Android dropper applications that utilize automated build rotation to bypass file hash-based detection. The rule identifies stable artifacts, such as specific native library names, string obfuscation indicators, and manifest structure anomalies, that persist across these regenerated builds.
Detects a specific Android sandbox escape technique where a malicious app enables Accessibility Services and Developer Options/Wireless Debugging to initiate a self-pairing ADB connection over localhost. This bypasses typical app sandbox restrictions, allowing the execution of processes with the UID 2000 (shell) context.
